CVE-2014-9016
Drupal < 7.34 - Denial of Service
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
The password hashing API in Drupal 7.x before 7.34 and the Secure Password Hashes (aka phpass) module 6.x-2.x before 6.x-2.1 for Drupal allows remote attackers to cause a denial of service (CPU and memory consumption) via a crafted request.
La API del hasheo de contraseñas en Drupal 7.x anterior a 7.34 y el módulo Secure Password Hashes (también conocido como phpass) 6.x-2.x anterior a 6.x-2.1 para Drupal permite a atacantes remotos causar una denegación de servicio (consumo de CPU y memoria) a través de una solicitud manipulada.
A vulnerability present in Drupal versions prior to 7.34 and WordPress versions prior to 4.0.1 allows an attacker to send specially crafted requests resulting in CPU and memory exhaustion. This may lead to the site becoming unavailable or unresponsive (denial of service).
CVSS Scores
SSVC
- Decision:-
Timeline
- 2014-11-20 CVE Reserved
- 2014-11-20 CVE Published
- 2014-12-01 First Exploit
- 2024-08-06 CVE Updated
- 2024-11-22 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
CAPEC
References (11)
URL | Tag | Source |
---|---|---|
http://secunia.com/advisories/59164 | Third Party Advisory | |
http://secunia.com/advisories/59814 | Third Party Advisory | |
http://www.openwall.com/lists/oss-security/2014/11/20/21 | Mailing List | |
http://www.openwall.com/lists/oss-security/2014/11/20/3 | Mailing List | |
http://www.openwall.com/lists/oss-security/2014/11/21/1 | Mailing List | |
https://nvd.nist.gov/vuln/detail/CVE-2014-9034 |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/35415 | 2014-12-01 |
URL | Date | SRC |
---|---|---|
https://www.drupal.org/node/2378367 | 2021-04-20 | |
https://www.drupal.org/node/2378375 | 2021-04-20 |
URL | Date | SRC |
---|---|---|
http://www.debian.org/security/2014/dsa-3075 | 2021-04-20 | |
https://www.drupal.org/SA-CORE-2014-006 | 2021-04-20 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Drupal Search vendor "Drupal" | Drupal Search vendor "Drupal" for product "Drupal" | >= 7.0 < 7.34 Search vendor "Drupal" for product "Drupal" and version " >= 7.0 < 7.34" | - |
Affected
| ||||||
Secure Password Hashes Project Search vendor "Secure Password Hashes Project" | Secure Passwords Hashes Search vendor "Secure Password Hashes Project" for product "Secure Passwords Hashes" | >= 6.x-2.0 < 6.x-2.1 Search vendor "Secure Password Hashes Project" for product "Secure Passwords Hashes" and version " >= 6.x-2.0 < 6.x-2.1" | drupal |
Affected
| ||||||
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 7.0 Search vendor "Debian" for product "Debian Linux" and version "7.0" | - |
Affected
|